What do we know about Kaenlupuf ransomware virus so far?
Today we are going to present a Malaysian ransomware[1] called Kaenlupuf virus. This suspicious and malicious program seems to be in the development process at the moment, but there’s no doubt that it is going to be improved and distributed on a much larger scale shortly[2]. The ransomware name stands for KAsi ENkrip LU PUnya File. The ransomware claims to be using a RSA-2048 encryption algorithm to corrupt files on the target computer, and this cryptography method[3] is known to be one of the most secure ones. Once files are encrypted, there are barely any chances to restore them without having a decryption key. The ransomware authors have it, so they ask the victim to pay a ransom of 1 BTC to their Bitcoin wallet. The ransom note that the virus creates after the encryption procedure says that the computer user “was chosen to be among the ones who got their files protected from external threats.” The criminals ramble about a special package available for an affordable price of 1 BTC[4] that the victim needs to purchase, while in reality, these crooks are just asking for a ransom of approximately 1170 USD. Below, you can see the ransom note (written in Malaysian language):
NOTE UNTUK ANDA – WAJIB BACA
Pertama sekali kami mengucapkan tahniah kepada anda kerana terpilih menjadi antara sebahagian yang berjaya melindungi fail-fail daripada ancaman luaran.
Kami amat mamahami anda memerlukan fail fail tersebut dengan segera. Dengan itu kami memperkenalkan pakej istimewa dengan harga mampu milik iaitu serendah 1 bitcoin sahaja.
Terkejut dengan tawaran kami? jadi apa tunggu lagi, daftar bitcoin anda sekarang untuk mendapat lebih nilai disamping fail-fail penting anda.
Lebih lama anda tunggu nilai akan semakin meningkat. fail-fail anda telah dilindungi dengan algoritma rsa-2048 bit. sangat selamat dan menarik bukan?
DAPATKAN SEMULA FAIL SAYA!
Untuk mendapatkan semula fail-fail anda, ikuti langkah berikut dengan cermat:
1. Daftar akaun Bitcoin wallet anda di url berikut:
2. Guna alamat bitcoin kami untuk memindahkan kredit anda:
3. Jumlah bayaran ialah seperti berikut:
4. Pastikan anda memaklumkan ID anda ketika membuat transaksi.

It goes without saying that you shouldn’t pay ransomware crooks the money they don’t deserve. Instead, we suggest removing the virus using anti-malware tools, for instance, FortectIntego, and recovering your files from a backup. Besides, malware analysts might successfully reverse this piece of malware and create a free decryption tool anytime soon, so we suggest you stay patient. You should start Kaenlupuf removal by rebooting your PC into Safe Mode with Networking. You can find full and comprehensive instructions on how to remove Kaenlupuf ransomware right below the article.
How can you get infected with ransomware virus?
Ransomware viruses are mostly distributed via deceptive email messages, but you can also become a victim of a ransomware attack due to RDP attack[5] or in case you have some outdated software on your PC, and you like to browse through shady Internet websites without having a decent anti-malware or antivirus software on your computer system. This way, your security vulnerabilities in the software you have can be easily exploited by attackers. We suggest you to protect your files in advance by creating a data backup, installing a good security software, and staying away from suspicious content online. Of course, you should also make sure that software you have is up-to-date (especially Flash or Java).
Kaenlupuf ransomware removal tutorial
Below the article, you can find a full Kaenlupuf removal tutorial which we prepared with an intention to clarify how ransomware viruses should be removed. Please do not try to remove Kaenlupuf virus without anti-malware software – it is very hard to delete such viruses by yourself, and you can easily do more bad than good when trying to solve the problem by yourself. If you have any questions about this virus, don’t hesitate and send a question to 2-Spyware support team or leave your questions or observations below.
Did this guide help?
4 comments
luvoi
very strange ransomware variant, gotta say!
38304
1 Bitcoin?????? Kaenlupuf devs gotta be kidding me. I aint paying such sum for scammers, cmon.
6degrees
ya Kaenlupuf devs seem to be greedy.
Bali
Removed the ransomware, but files are gone... so sad.... I cannot even believe it...